Polyglot Desk — Privacy Policy
This Privacy Policy explains how the Polyglot Desk browser extension ("the Extension") handles data on your behalf. The Extension is published by Legendary Feather, a Mexican individual with business activity (Persona Física con Actividad Empresarial). It is offered through the Chrome Web Store and other extension marketplaces.
This policy applies specifically to the Polyglot Desk browser extension. The Legendary Feather Traveler web application is governed by its own Privacy Policy.
1. Data Controller
Legendary Feather, operating as a Persona Física con Actividad Empresarial registered in Mexico, is the controller of any personal data processed in connection with the Extension.
Contact: legal@legendaryfeather.com
2. The Two Modes
2.1 Free trial (bring your own key)
You paste your own Groq API key (free at console.groq.com) into the Extension. It is stored only in chrome.storage.local on your device. Text you process and audio you dictate are sent directly from your browser to Groq under Groq’s terms. They do not pass through Legendary Feather servers, and we never see your key.
2.2 Paid membership (Pro or Business)
You sign in and we run the AI for you using our own server key. Requests travel: Extension → Legendary Feather backend (Supabase Edge Functions) → Groq. You do not provide or handle any API key.
3. What We Collect
3.1 Account information (members only)
- Email address, and optionally a display name.
- Sign-in is passwordless — we email you a one-time code (OTP). We never create or store a password.
- Your plan tier (Free, Pro, or Business) and subscription status.
- Your interface and translation language preferences.
3.2 Usage metadata (members only)
To operate the service, enforce quotas, and prevent abuse, our backend logs a minimal record of each request: which feature was used (grammar, translate, voice), which model served it, and a timestamp. We do not log the content of your messages.
3.3 What stays on your device
Stored only in chrome.storage.local, sandboxed to the Extension and inaccessible to web pages:
- Your Groq API key, if using the free trial.
- Your settings — languages, feature toggles, agent name and tone, dashboard language.
- Your personal phrase bank, Teach rules, translation memory (phrases you edited and saved for reuse), and clipboard history.
- Your session token, if signed in.
3.4 Shared team response bank (Business only)
On the Business plan, phrases you deliberately add to the shared bank are stored in our database so your teammates can use them. Access is enforced server-side by row-level security and is restricted to accounts on an active Business plan. Nothing is shared unless you explicitly add it.
4. Voice and Text Handling
- Voice dictation. Microphone audio is captured locally in your browser and transcribed by Groq Whisper Large v3 Turbo. The audio is processed in real time and not retained after the transcription is returned — not by us, and not stored by the Extension.
- Grammar, rewrite, translation and autocomplete are produced by Groq large-language models (Llama family). We do not store the content of your messages on our servers.
- Polyglot Desk does not synthesize speech (no text-to-speech) and does not perform voice cloning.
5. Third-Party Sub-Processors
| Purpose | Provider | Data sent |
|---|---|---|
| AI text processing and speech-to-text | Groq, Inc. (USA) | The text you process, or the audio you dictate |
| Authentication, database, managed backend | Supabase, Inc. (USA) | Email, plan, usage metadata, shared phrases |
| Payment processing | Stripe, Inc. (USA) | Handled entirely by Stripe; we never see your card number |
| Address preview (geocoding) | OpenStreetMap / Mapbox | The detected address string only |
| DNS and edge protection | Cloudflare, Inc. (USA) | Standard connection metadata |
Each provider is bound by its own privacy policy and, where applicable, a Data Processing Agreement. Where data is transferred outside the EEA we rely on Standard Contractual Clauses.
6. Payments
Payment is handled exclusively by Stripe. We never see or store your full card number. We retain only the Stripe customer ID, your plan, and your subscription status.
7. What the Extension Does NOT Do
- No telemetry beyond the minimal usage metadata described in 3.2.
- No analytics — no Google Analytics, PostHog, Mixpanel, or crash reporters calling home.
- No advertising — we don’t sell, share, or rent your data to advertisers, and we display no ads.
- No browsing history. Although the manifest declares
<all_urls>access (required for the content script that works inside text fields on any site), we do not read, store, or transmit the pages you visit. - No background scraping. The Extension acts only when you trigger it.
8. Permissions Explained
contextMenus— adds the "Correct selection" right-click entry.storage— saves your settings, phrase bank, and session locally.activeTab— interacts with the page you are currently viewing.scripting— injects the content script where the static one cannot run (e.g. Google Docs).windows/tabs— opens the detached translator and routes results to the right tab.alarms— refreshes your session in the background.<all_urls>host permission — required so corrections, translation and autocomplete work in the text fields of whatever tool you use (your CRM, Gmail, Front, etc.).
9. Microphone Access
When you start voice dictation the Extension requests microphone access through the browser’s standard getUserMedia() prompt. The microphone is active only while dictation is running. The recording is sent for transcription and then discarded; it is never stored by the Extension or on our servers.
10. Data Retention
- Audio — not retained; discarded once transcribed.
- Message content — not stored on our servers.
- Account data — kept while your account is active and up to 6 months after deletion.
- Usage metadata and audit logs — up to 90 days, then purged.
- Billing records — 5 years (Mexican fiscal law) or local equivalent.
- Local data — uninstalling the Extension removes everything in
chrome.storage.local. You can also clear individual items from the Extension’s settings at any time.
11. Your Rights
If you only ever used the free trial with your own key, we hold no data about you on our servers. If you subscribed, you have the right to access, rectify, erase, port, restrict, or object to the processing of your data, and to withdraw consent at any time. Email legal@legendaryfeather.com from the address on your account; we respond within 30 days. You may also lodge a complaint with your local supervisory authority (Mexican INAI, Spanish AEPD, French CNIL, California Attorney General, or equivalent).
12. Security
- All traffic is encrypted in transit (TLS 1.2+).
- Sessions use signed JWTs that rotate on login.
- Access to the shared team bank is enforced server-side by row-level security.
- Manifest V3 — service worker isolation, no remote code execution, declarative content scripts.
- The Content Security Policy restricts outbound connections to a strict allowlist (Groq, our Supabase backend, OpenStreetMap and Mapbox).
No system is perfectly secure. If you believe your account has been compromised, email us immediately.
13. Children
The Extension is not intended for users under 16. We do not knowingly collect personal data from children under 16.
14. International Transfers
Our sub-processors operate servers in the United States and other countries, so using the Service involves transferring your data there. We rely on Standard Contractual Clauses where required by EU law. On the free trial, the transfer happens directly between you and Groq.
15. Changes to This Policy
We update this policy whenever the Extension’s data handling changes — a new provider, a new tier, a new optional feature. Material changes are announced in the release notes on the Chrome Web Store and through a notice in the popup the first time you open the new version.
16. Contact
Privacy questions, complaints, or rights requests related specifically to the Polyglot Desk extension:
legal@legendaryfeather.com (subject line: "Polyglot Desk privacy")
